CVE-2018-3819: Elastic Kibana

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.

Affected products

  • Elastic Kibana: before 5.6.7 (fixed in 5.6.7); from 6.0.0, before 6.1.3 (fixed in 6.1.3)

Published 2018-03-30. Last modified 2026-06-17.